{"id":118928,"date":"2017-09-21T23:52:39","date_gmt":"2017-09-22T03:52:39","guid":{"rendered":"https:\/\/canadianinquirer.net\/v1\/?p=118928"},"modified":"2017-09-21T23:52:39","modified_gmt":"2017-09-22T03:52:39","slug":"sec-under-fire-for-being-hacked-despite-warnings-on-security","status":"publish","type":"post","link":"https:\/\/canadianinquirer.net\/v1\/2017\/09\/21\/sec-under-fire-for-being-hacked-despite-warnings-on-security\/","title":{"rendered":"SEC under fire for being hacked despite warnings on security"},"content":{"rendered":"<figure id=\"attachment_118937\" aria-describedby=\"caption-attachment-118937\" style=\"width: 480px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/canadianinquirer.net\/v1\/wp-content\/uploads\/2017\/09\/480px-Seal_of_the_United_States_Securities_and_Exchange_Commission.svg_.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-118937\" src=\"https:\/\/canadianinquirer.net\/v1\/wp-content\/uploads\/2017\/09\/480px-Seal_of_the_United_States_Securities_and_Exchange_Commission.svg_.png\" alt=\"The Securities and Exchange Commission waited until Wednesday to disclose a hack of its corporate filing system that occurred last year. (Photo By U.S. Government, Public Domain)\" width=\"480\" height=\"480\" srcset=\"https:\/\/canadianinquirer.net\/v1\/wp-content\/uploads\/2017\/09\/480px-Seal_of_the_United_States_Securities_and_Exchange_Commission.svg_.png 480w, https:\/\/canadianinquirer.net\/v1\/wp-content\/uploads\/2017\/09\/480px-Seal_of_the_United_States_Securities_and_Exchange_Commission.svg_-150x150.png 150w, https:\/\/canadianinquirer.net\/v1\/wp-content\/uploads\/2017\/09\/480px-Seal_of_the_United_States_Securities_and_Exchange_Commission.svg_-300x300.png 300w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/a><figcaption id=\"caption-attachment-118937\" class=\"wp-caption-text\">The Securities and Exchange Commission waited until Wednesday to disclose a hack of its corporate filing system that occurred last year. <a href=\"https:\/\/commons.wikimedia.org\/w\/index.php?curid=8928191\">(Photo By U.S. Government, Public Domain)<\/a><\/figcaption><\/figure>\n<p>WASHINGTON \u2014 The Securities and Exchange Commission waited until Wednesday to disclose a hack of its corporate filing system that occurred last year. The disclosure raises questions about the agency&#8217;s ability to protect important financial information and comes as Americans are still weighing the consequences of the massive hack at Equifax.<\/p>\n<p>The SEC, the federal agency responsible for protecting investors and ensuring markets function properly, is under fire after disclosing the hack of its electronic network that whisks company news and data to investors. The breach occurred despite repeated warnings in recent years about weaknesses in the agency&#8217;s cybersecurity controls.<\/p>\n<p>Experts question the length of time taken to disclose the breach, and why the SEC isn&#8217;t meeting the same security standards it demands of corporate America.<\/p>\n<p>\u201cPublic companies have a clear obligation to disclose material information about cyber risks and cyber events. I expect them to take this requirement seriously,\u201d SEC Chairman Jay Clayton warned in a speech in July.<\/p>\n<p>While it discovered the breach to its corporate filing system last year, the agency says it only became aware last month that information obtained by the intruders may have been used for illegal trading profits.<\/p>\n<p>\u201cIt took quite a while,\u201d said Robert Cattanach, an attorney at Dorsey &amp; Whitney and former trial attorney for the Justice Department, whose work includes cybersecurity and data breaches. \u201cThe integrity of our whole trading system is dependent on keeping this information secure. &#8230; People have got some &#8216;splaining to do.\u201d<\/p>\n<p>The SEC didn&#8217;t explain why the initial hack was not revealed sooner, or which individuals or companies may have been affected. The disclosure came two months after a government watchdog said deficiencies in the corporate filing system put the system, and the information it contains, at risk.<\/p>\n<p>The agency also didn&#8217;t disclose any information about who might have carried out the breach. A hack by Chinese or Russian actors can&#8217;t be ruled out, experts say.<\/p>\n<p>\u201cCertainly state actors would be on the list of suspects that come to mind,\u201d said Marcus Christian, a former federal prosecutor who is an attorney working in Mayer Brown&#8217;s cybersecurity and national security practices. Still, he added, the list also would include \u201cregular old criminal actors.\u201d<\/p>\n<p>U.S. prosecutors in Manhattan brought criminal charges last December against three Chinese traders, accusing them of using nonpublic information stolen from two New York law firms to rack up nearly $3 million in illegal profits. The SEC filed a similar civil action, marking the first time the agency laid charges of hacking into a law firm&#8217;s computer network. The confidential information was said to be linked to clients of the firm considering mergers or acquisitions.<\/p>\n<p>Clayton disclosed the hack in a statement posted to the SEC&#8217;s website. It comes just two weeks after the credit agency Equifax revealed a stunning cyberattack that exposed highly sensitive personal information of 143 million people.<\/p>\n<p>Clayton is scheduled to appear Tuesday before the Senate Banking Committee, and he is certain to be questioned about the hack. Democratic Sen. Mark Warner of Virginia, a member of the committee, said in a statement Thursday that the disclosures by the SEC and Equifax show \u201cthat government and businesses need to step up their efforts to protect our most sensitive personal and commercial information.\u201d<\/p>\n<p>The SEC chief blamed the breach on \u201ca software vulnerability\u201d in the filing system known as EDGAR, short for Electronic Data Gathering, Analysis and Retrieval system. EDGAR processes more than 1.7 million electronic filings a year. Those documents can cause enormous movements in the stock market, sending billions of dollars into motion in fractions of a second.<\/p>\n<p>Clayton, a Wall Street attorney appointed by President Donald Trump to the SEC post, said the agency has been assessing its cybersecurity since he took over as chairman in May. Experts note, however, that both agency and congressional investigators have been critical for years of the SEC&#8217;s handling of its information technology security.<\/p>\n<p>Early this decade, the SEC inspector general&#8217;s office uncovered security lapses involving SEC staffers who examined the data-protection systems of the stock exchanges. Some of the staffers used unencrypted laptops to store sensitive exchange information \u2014 and then carried the laptops to a Las Vegas conference for information-security professionals that is known to attract hackers. The 2011-12 investigation raised concerns of a potential breach of the exchanges&#8217; information.<\/p>\n<p>David Weber, a professor at the University of Maryland&#8217;s business school and a former assistant SEC inspector general for investigations, worked on that probe. The agency \u201cclearly has not held itself to the same standard that it expects regulated companies to adhere to\u201d and \u201cneeds to up its game,\u201d he said in an interview Thursday.<\/p>\n<p>In 2015, an impostor slipped through the EDGAR filing system with a bogus $8 billion takeover bid for Avon Products. The stock rocketed 20 per cent, but it quickly dropped, burning anyone who&#8217;d bought shares of the cosmetics giant at pumped-up prices. The SEC later sued a Bulgarian investor for allegedly orchestrating bogus acquisition bids for Avon and two other companies.<\/p>\n<p>The hack of EDGAR is especially concerning because of how widely investors have used and trusted the system, which first came online in the early 1990s. Companies periodically file earnings and a range of financial information, and they alert investors to important developments that could affect their share prices, like government investigations, executive shake-ups and approaches for a takeover.<\/p>\n<p>Some experts say gaining access to the system is too easy and the SEC should consider stricter vetting, though they caution that doing so wouldn&#8217;t guarantee blocking scammers from getting through.<\/p>\n<p>Experts say stricter requirements could include passwords, personal ID, secret questions and answers, security tokens that continuously flash new ID numbers, fingerprints, eye scans or voice recognition.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WASHINGTON \u2014 The Securities and Exchange Commission waited until Wednesday to disclose a hack of its corporate filing system that &hellip;<\/p>\n","protected":false},"author":33,"featured_media":118937,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24157,16,17],"tags":[20575,14983,24521],"class_list":["post-118928","post","type-post","status-publish","format-standard","has-post-thumbnail","category-american-news","category-news","category-news-w","tag-hacked","tag-securities-and-exchange-commission","tag-warnings-on-security","mauthors-marcy-gordon","mauthors-the-associated-press"],"_links":{"self":[{"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/posts\/118928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/comments?post=118928"}],"version-history":[{"count":0,"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/posts\/118928\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/media\/118937"}],"wp:attachment":[{"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/media?parent=118928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/categories?post=118928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/canadianinquirer.net\/v1\/wp-json\/wp\/v2\/tags?post=118928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}